Updated: 27 March 2026
What do recent high-profile cybersecurity breaches have in common? In most major incidents, the decisive failure was not exotic malware. It was an ordinary weakness left unchallenged long enough to become strategic: a helpdesk identity check that did not exist, a trusted file-transfer tool that became a systemic supplier risk, a backup regime that collapsed when restoration mattered, or an attacker who remained inside an environment for months before activating destruction. These incidents are not just news stories – they are board papers in public. They show which decisions shaped the outcome, what the breach actually cost, and what a better-prepared organisation would have done differently.
Cybersecurity breach case studies – at a glance:
- MGM Resorts, September 2023: a single helpdesk phone call triggered more than USD 100 million in losses over ten days – technology controls did not fail first, process did
- MOVEit, May 2023 (CVE-2023-34362): one trusted file-transfer product became an attack path into more than 2,700 organisations globally – Cl0p exploited a zero-day; victims included the BBC, British Airways, Boots, and the NHS
- Indonesia National Data Centre, June 2024: an USD 8 million ransom demand; 282 public services disrupted; recovery revealed that much of the affected data had not been properly backed up
- Kyivstar, December 2023: Sandworm (Russian GRU-linked) disrupted mobile services for 24 million subscribers – attackers had maintained access since at least May 2023 (Reuters, 2024)
- In every case, the most expensive cost element was delay, not the first technical error
- Reputation multiplies operational loss – how a company manages communication after a breach has economic consequences comparable to the breach itself
- All four attack vectors – social engineering, supply-chain compromise, backup failure, long-dwell persistence – are known, fixable, and not exotic
Table of Contents
What happened in the MGM Resorts cyberattack and what is the board lesson?
MGM Resorts disclosed in regulatory filings that the cyberattack in September 2023 would have a negative impact of roughly USD 100 million on its third-quarter results – mostly from lost revenue at its Las Vegas properties. Guests could not reliably access room keys, slot machines were affected, booking systems were disrupted, and internal systems had to be taken offline. The disruption lasted days, not months. That is what makes the case so useful: one short window of operational paralysis was enough to become a nine-figure event.
Public reporting tied the intrusion to Scattered Spider (also tracked as UNC3944), a financially motivated threat actor known for aggressive social engineering. Attackers reportedly identified an MGM IT helpdesk employee via LinkedIn, called the helpdesk, impersonated the employee, and convinced the organisation to reset credentials. Technology controls did not fail first – process failed first, and technology followed.
CEOs often think of helpdesk identity verification as an IT operations detail. It is not. If a caller can persuade your organisation to hand over access, the attacker has found the cheapest route around expensive controls.
The fix: Implement a formal helpdesk identity-verification workflow for password resets, MFA resets, and privileged account changes. Require callback to a registered number, manager approval for high-risk changes, and a prohibition on single-channel identity proof.
How did the MOVEit zero-day affect more than 2,700 organisations through one trusted tool?
Progress Software disclosed a critical vulnerability in MOVEit Transfer on 31 May 2023 – later tracked as CVE-2023-34362. The flaw was rapidly exploited by the Cl0p ransomware group. Victims included the BBC, British Airways, Boots, the NHS supply-chain ecosystem, and the US Department of Energy. IBM’s 2024 Cost of a Data Breach Report put the average cost of a breach involving a zero-day vulnerability at USD 4.76 million, which helps explain why a supplier-side event can create extraordinary aggregate damage (IBM 2024).
This case overturns a common executive assumption: that being fully patched internally means you are safe. The weak point was not a neglected server in a forgotten office. It was a trusted enterprise tool built for secure data movement. Attackers exploited that trust.
The fix: Build a dependency map for critical suppliers and software – not just a vendor list. Identify which external platforms process sensitive data, which are business-critical, and which could create cross-client blast radius. Then define emergency actions in advance: isolation steps, fallback processes, legal contacts, and the threshold for notifying customers when the failure originates upstream.
What does the Indonesia National Data Centre attack reveal about backup strategies?
In June 2024, Indonesia’s National Data Centre suffered a ransomware attack associated with Brain Cipher (a LockBit 3.0 variant). Attackers demanded an USD 8 million ransom. Indonesian officials later acknowledged that much of the affected data had not been properly backed up or was not recoverable in practice. 282 government services were disrupted, including immigration functions. The incident became severe enough to trigger a presidential audit and broader questions about ministerial accountability.
Companies often say with confidence that they back up everything important. That answer is not strong enough. The only answer that matters is whether the business can restore the right systems, in the right order, within the right time. A ransomware event exposes the difference between backup coverage and recovery capability with brutal clarity.
The fix: Test restoration against your five most critical systems at least annually in a way that simulates hostile loss rather than convenient admin recovery. Measure actual restoration time, data integrity, credential dependencies, and the order in which services come back.
What does the Kyivstar attack demonstrate about long-dwell persistence threats?
On 12 December 2023, Kyivstar, Ukraine’s largest mobile operator, suffered a destructive cyberattack that knocked services offline for roughly 24 million subscribers. Reuters later reported that the company allocated about USD 90 million to deal with the aftermath. Ukrainian officials attributed the attack to Sandworm, the Russian GRU-linked cyberwarfare unit.
Reporting indicated the attackers had established access well before activation – likely through a compromised employee account – and remained in the environment for months before the most visible effects appeared. Many executive teams over-trust clean dashboards. If there are no visible alerts today, they assume there is no adversary inside. Kyivstar is the counterexample. Sophisticated attackers do not need to announce themselves immediately.
The fix: Combine identity hardening with regular threat hunting, network segmentation, and special protection for high-impact administrative actions. The board question should not be only “Are we patched?” It should be “How would we know if someone has already been inside for ninety days?” Learn more about penetration testing services and vulnerability scanning.
What is the common pattern behind every major cybersecurity breach?
Three structural patterns appear across all four cases. First, the attack vectors are known. Social engineering, third-party software exploitation, backup failure, and attacker persistence are not science-fiction scenarios – they are ordinary weaknesses expressed at extraordinary scale. Second, the most damaging cost comes from delay rather than from the first technical error: delay in verifying identity, in mapping supplier dependency, in proving restoration capability, in detecting that an attacker already has access. Third, reputation multiplies operational loss. Boards sometimes treat communications as a soft issue compared with containment. Customers, regulators, insurers, lenders, and partners judge not only whether a company was breached, but how clearly it understood the risk and how quickly it communicated.
Prepared companies look different before an incident, not during one. They harden mundane processes, know where critical dependencies sit, test restoration under pressure, assign ownership clearly, and rehearse executive communications before the market forces them to improvise.
FAQ
What happened in the MGM Resorts cyberattack in 2023?
Attackers linked to Scattered Spider / UNC3944 used social engineering against MGM’s IT helpdesk in September 2023, obtained credential resets, and triggered a disruption that MGM later said would have a roughly USD 100 million impact on third-quarter results. The board lesson is that identity verification at the helpdesk is a critical control, not an administrative detail.
How did the MOVEit hack affect so many companies?
A zero-day vulnerability in Progress MOVEit Transfer (CVE-2023-34362), disclosed on 31 May 2023, was exploited by Cl0p – allowing one trusted enterprise tool to become an access route into thousands of customer environments and data flows. More than 2,700 organisations were affected globally.
What caused the Indonesia National Data Centre breach?
Public reporting tied the June 2024 incident to a Brain Cipher ransomware attack using a LockBit 3.0 variant. The case became a resilience lesson because recovery difficulties exposed weak or missing backup capability across affected public services.
Who is Sandworm and what did they do to Kyivstar?
Public reporting tied the June 2024 incident to a Brain Cipher ransomware attack using a LockBit 3.0 variant. The case became a resilience lesson because recovery difficulties exposed weak or missing backup capability across affected public services.
What is the most expensive cyberattack in history?
There is no single universally accepted answer. NotPetya in 2017 is widely cited as one of the most expensive on record, with global damage estimates around USD 10 billion. It remains the benchmark for how destructive cyber operations spill far beyond the intended target.
How can organisations detect a long-dwell attacker who has been inside for months?
Combine identity hardening with regular threat hunting using endpoint detection and response (EDR) tooling, privileged-access monitoring, network segmentation, and targeted threat-hunting activity to look for long-dwell indicators. The board question is not only “Are we patched?” but “How would we know if someone has been inside for ninety days?”
Breach readiness assessment – free sector-specific briefing
Patronusec can assess which of these case-study patterns is most relevant to your industry, supply chain, and compliance obligations – and show you which gaps are most likely to be exploited first.
Book a no-commitment call with our team.